CVE WATCH / VULNERABILITY DETAIL

CVE-2026-93348

HIGHCVSS 8.1NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

CVE-2026-93348 — Vulnerability Details | Logic Encoder
CVE WATCH / VULNERABILITY DETAIL

CVE-2026-93348

HIGHCVSS 8.1NVD feed

Published 28 September 2026 · tracked since 28 September 2026

Description

Unsloth Zoo versions 2025.9.9 before 2026.8.14, as implemented in Unsloth 2025.9.9 through 2026.8.19, contains a code injection vulnerability in the model-loading compile path where the get_transformers_model_type() function in hf_utils.py collects model_type values from nested model configurations

References

Latest tracked vulnerabilities

→ Open the live CVE board · all tools

[an error occurred while processing this directive]